MARYLANDMalwareHealthcareHealthcareCustomer Data InvolvedDelayed DiscoveryHEALTH_BASICIDENTITY_BASICHighResolved
LIFEBRIDGE HEALTH, INC.
bd_9aba90d5aceb53c5 · schema v1 · pii pii-v1
Full breach record for LIFEBRIDGE HEALTH, INC. →LifeBridge Health, Inc. (MD) reported to HHS OCR on 2018-05-15 a Hacking/IT Incident (malware attack on a network server hosting electronic medical records) affecting 538,127 individuals. An unauthorized person accessed the server on September 27, 2016; the breach was not discovered until March 2018. PHI involved included demographic and clinical information. OCR reviewed compliance with Privacy and Security Rules and obtained assurances of corrective actions, including increased password controls and contingency/disaster-recovery procedures.
HIPAA clockDiscovered Mar 1, 2018 → Notified May 15, 201875d ✗ HIPAA 60-day late11 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_018a5d74fcf1990dCalifornia State AGfiled 2018-05-15Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 15, 2018
- Raw hash
- bfa0357f34f2a953780c84618567184050460150f1538134da8b6792267796a4
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- LIFEBRIDGE HEALTH, INC.norm: lifebridge health
- Domain
- lifebridgehealth.org
- Industry
- Health Care Services
Victim entity
- Name
- LIFEBRIDGE HEALTH, INC.norm: lifebridge health
- Domain
- lifebridgehealth.org
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Mar 1, 2018
- Materiality determined
- —
- Notification sent
- May 15, 2018
- Affected individuals
- 538,127
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- HHS OCR reviewed the CE's policies and procedures to ensure compliance with the Privacy and Security Rules; OCR obtained assurances that the CE implemented corrective actions.
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- HIPAA 60-day late · 75dHHS notified · 75d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Mar 1, 2018→ Notified: May 15, 201875d 60 days HIPAA 60-day late HIPAA Discovered: Mar 1, 2018→ Notified: May 15, 201875d regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.